Software /
code /
prosody-modules
Changeset
6094:7adab72d5ebe
mod_warn_legacy_tls: Update Examples and Introduction for current TLS versions.
author | Menel <menel@snikket.de> |
---|---|
date | Mon, 16 Dec 2024 13:06:23 +0100 |
parents | 6093:c359259a494d |
children | 6095:b048767a69b0 |
files | mod_warn_legacy_tls/README.md |
diffstat | 1 files changed, 21 insertions(+), 2 deletions(-) [+] |
line wrap: on
line diff
--- a/mod_warn_legacy_tls/README.md Thu Dec 12 21:34:50 2024 +0100 +++ b/mod_warn_legacy_tls/README.md Mon Dec 16 13:06:23 2024 +0100 @@ -1,5 +1,13 @@ -TLS 1.0 and TLS 1.1 are about to be obsolete. This module warns clients -if they are using those versions, to prepare for disabling them. +--- +labels: +- Stage-Alpha +summary: Warn users of obsolete TLS Versions in clients +--- + + +TLS 1.0 and TLS 1.1 are obsolete. This module warns clients if they are using those versions, to prepare for disabling them. (If you use the default prosody config this module will be unnessesary in its default config, since these protocols are not allowed anymore by any supported prosody version. + +This module can be used to warn from TLS1.2 if you want to switch to modern security in the near future. # Configuration @@ -15,6 +23,10 @@ legacy_tls_warning = [[ Your connection is encrypted using the %s protocol, which has been demonstrated to be insecure and will be disabled soon. Please upgrade your client. ]] + +--You may want to warn about TLS1.2 these days too (This note added 2024), by default prosody will not even allow connections from TLS <1.2 +--Example: +legacy_tls_versions = { "TLSv1", "TLSv1.1", "TLSv1.2" } ``` ## Options @@ -26,3 +38,10 @@ `legacy_tls_versions` : Set of TLS versions, defaults to `{ "SSLv3", "TLSv1", "TLSv1.1" }`{.lua}, i.e. TLS \< 1.2. + +# Compatibility + +Prosody-Version Status +--------------- --------------------- +trunk Works as of 24-12-16 +0.12 Works